Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
tar could be made to overwrite files if it opened a specially crafted archive.. ========================================================================== Ubuntu Security Notice USN-8477-1 June 25, 2026 tar vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: tar could be made to overwrite files if it opened a specially crafted archive. Software Description: - tar: GNU tar archive utility Details: It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS tar 1.35+dfsg-4ubuntu0.1 Ubuntu 24.04 LTS tar 1.35+dfsg-3ubuntu0.1 Ubuntu 22.04 LTS tar 1.34+dfsg-1ubuntu0.1.22.04.3 Ubuntu 20.04 LTS tar 1.30+dfsg-7ubuntu0.20.04.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS tar 1.29b-2ubuntu0.4+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS tar 1.28-2.1ubuntu0.2+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS tar 1.27.1-1ubuntu0.1+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8477-1 CVE-2026-5704 Package Information: https://launchpad.net/ubuntu/+source/tar/1.35+dfsg-4ubuntu0.1 https://launchpad.net/ubuntu/+source/tar/1.35+dfsg-3ubuntu0.1 https://launchpad.net/ubuntu/+source/tar/1.34+dfsg-1ubuntu0.1.22.04.3 . Ubuntu's tar utility faces a critical flaw allowing file overwrites via crafted archives. Update your system now.. Ubuntu Tar Security Update, Critical Tar Vulnerability, Secure File Archiving. . Severity: Critical. LinuxSecurity.com Team
jaraco.context could be made to overwrite files.. ========================================================================== Ubuntu Security Notice USN-7979-1 January 27, 2026 jaraco.context vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: jaraco.context could be made to overwrite files. Software Description: - jaraco.context: context managers extending functionality of Python's contextlib Details: It was discovered that jaraco.context incorrectly handled certain zip file paths. An attacker could possibly use this issue to extract arbitrary files outside of the intented extraction directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-jaraco.context 6.0.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7979-1 CVE-2026-23949 Package Information: https://launchpad.net/ubuntu/+source/jaraco.context/6.0.1-1ubuntu0.1 . A critical file overwriting flaw in jaraco.context impacts Ubuntu 25.10. Immediate updates required to ensure security.. Ubuntu security, jaraco.context update, file access issues, Python context managers. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for podman Announcement ID: SUSE-SU-2025:03584-1 Release Date: 2025-10-13T06:59:34Z Rating: important References: * bsc#1249154 Cross-References: * CVE-2025-9566 CVSS scores: * CVE-2025-9566 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-9566 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-9566 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for podman fixes the following issues: * CVE-2025-9566: fixed an issue in kube play command that could cause overwriting host files (bsc#1249154) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3584=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3584=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3584=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3584=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3584=1 * SUSE Linux Enterprise HighPerformance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3584=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3584=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3584=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3584=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-debuginfo-4.9.5-150400.4.53.1 * podmansh-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * openSUSE Leap 15.4 (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux EnterpriseHigh Performance Computing ESPOS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.53.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9566.html * https://bugzilla.suse.com/show_bug.cgi?id=1249154 . An important update for openSUSE that addresses a specific issue in Podman, enhancing system resilience.. openSUSE, podman, security update, important patch, CVE-2025-9566. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2025-9566 Automatic update for containers-common-0.64.2-1.fc41, buildah-1.41.4-1.fc41, podman-5.6.1-1.fc41. Changelog for containers-common * Wed Sep 03 2025 Packit - 5:0.64.2-1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f9e142a4b0 2025-09-09 01:41:14.778487+00:00 -------------------------------------------------------------------------------- Name : containers-common Product : Fedora 41 Version : 0.64.2 Release : 1.fc41 URL : https://github.com/containers/common Summary : Common configuration and documentation for containers Description : This package contains common configuration files and documentation for container tools ecosystem, such as Podman, Buildah and Skopeo. It is required because the most of configuration files and docs come from projects which are vendored into Podman, Buildah, Skopeo, etc. but they are not packaged separately. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2025-9566 Automatic update for containers-common-0.64.2-1.fc41, buildah-1.41.4-1.fc41, podman-5.6.1-1.fc41. Changelog for containers-common * Wed Sep 03 2025 Packit - 5:0.64.2-1 - Update to 0.64.2 upstream release Changelog for buildah * Thu Sep 04 2025 Packit - 2:1.41.4-1 - Update to 1.41.4 upstream release Changelog for podman * Thu Sep 04 2025 Packit - 5:5.6.1-1 - Update to 5.6.1 upstream release -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 3 2025 Packit - 5:0.64.2-1 - Update to 0.64.2 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2393153 - CVE-2025-9566 podman: Podman kube play command may overwrite host files [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393153 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f9e142a4b0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1224168 * bsc#1224170 * bsc#1224171 * bsc#1224172 * bsc#1224173 . # Security update for git Announcement ID: SUSE-SU-2025:0197-1 Release Date: 2025-01-21T10:03:39Z Rating: important References: * bsc#1224168 * bsc#1224170 * bsc#1224171 * bsc#1224172 * bsc#1224173 * bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-32002 * CVE-2024-32004 * CVE-2024-32020 * CVE-2024-32021 * CVE-2024-32465 * CVE-2024-50349 * CVE-2024-52006 CVSS scores: * CVE-2024-32002 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-32002 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2024-32004 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2024-32020 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L * CVE-2024-32021 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L * CVE-2024-32465 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-50349 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2024-50349 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-52006 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2024-52006 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for git fixes the following issues: * CVE-2024-32002: Fix recursive clones on case-insensitivefilesystems that support symbolic links are susceptible to case confusion. (bsc#1224168) * CVE-2024-32004: Fixed arbitrary code execution during local clones. (bsc#1224170) * CVE-2024-32020: Fix file overwriting vulnerability during local clones. (bsc#1224171) * CVE-2024-32021: Git may create hardlinks to arbitrary user-readable files. (bsc#1224172) * CVE-2024-32465: Fixed arbitrary code execution during clone operations. (bsc#1224173) * CVE-2024-50349: Passwords for trusted sites could be sent to untrusted sites (bsc#1235600). * CVE-2024-52006: Carriage Returns via the credential protocol to credential helpers (bsc#1235601). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-197=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-197=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * git-daemon-debuginfo-2.26.2-27.78.1 * git-debugsource-2.26.2-27.78.1 * git-svn-2.26.2-27.78.1 * git-daemon-2.26.2-27.78.1 * git-core-2.26.2-27.78.1 * git-2.26.2-27.78.1 * git-email-2.26.2-27.78.1 * git-cvs-2.26.2-27.78.1 * git-core-debuginfo-2.26.2-27.78.1 * git-web-2.26.2-27.78.1 * gitk-2.26.2-27.78.1 * git-gui-2.26.2-27.78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * git-daemon-debuginfo-2.26.2-27.78.1 * git-debugsource-2.26.2-27.78.1 * git-svn-2.26.2-27.78.1 * git-daemon-2.26.2-27.78.1 * git-core-2.26.2-27.78.1 * git-2.26.2-27.78.1 * git-email-2.26.2-27.78.1 * git-cvs-2.26.2-27.78.1 * git-core-debuginfo-2.26.2-27.78.1 * git-web-2.26.2-27.78.1 * gitk-2.26.2-27.78.1 *git-gui-2.26.2-27.78.1 ## References: * https://www.suse.com/security/cve/CVE-2024-32002.html * https://www.suse.com/security/cve/CVE-2024-32004.html * https://www.suse.com/security/cve/CVE-2024-32020.html * https://www.suse.com/security/cve/CVE-2024-32021.html * https://www.suse.com/security/cve/CVE-2024-32465.html * https://www.suse.com/security/cve/CVE-2024-50349.html * https://www.suse.com/security/cve/CVE-2024-52006.html * https://bugzilla.suse.com/show_bug.cgi?id=1224168 * https://bugzilla.suse.com/show_bug.cgi?id=1224170 * https://bugzilla.suse.com/show_bug.cgi?id=1224171 * https://bugzilla.suse.com/show_bug.cgi?id=1224172 * https://bugzilla.suse.com/show_bug.cgi?id=1224173 * https://bugzilla.suse.com/show_bug.cgi?id=1235600 * https://bugzilla.suse.com/show_bug.cgi?id=1235601 . Crucial security patches for Git resolve significant vulnerabilities found in SUSE. Immediate updates are accessible for impacted versions.. SUSE Linux Enterprise, Git Security Advisory, Vulnerability Fixes. . Severity: Important. LinuxSecurity.com Team
rsync fails to properly sanitize paths. This vulnerability could allow the listing of arbitrary files and allow file overwriting outside module's path on rsync server configurations that allow uploading. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200408-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: rsync: Potential information leakage Date: August 17, 2004 Bugs: #60309 ID: 200408-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= rsync fails to properly sanitize paths. This vulnerability could allow the listing of arbitrary files and allow file overwriting outside module's path on rsync server configurations that allow uploading. Background ========= rsync is a utility that provides fast incremental file transfers. It is used to efficiently synchronize files between hosts and is used by emerge to fetch Gentoo's Portage tree. rsyncd is the rsync daemon, which listens to connections from rsync clients. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/rsync = 2.6.0-r3 Description ========== The paths sent by the rsync client are not checked thoroughly enough. It does not affect the normal send/receive filenames that specify what files should be transferred. It does affect certain option paths that cause auxilliary files to be read or written. Impact ===== When rsyncd is used without chroot ("use chroot = false" in the rsyncd.conf file), this vulnerability could allow the listing of arbitrary files outside module's path and allowfile overwriting outside module's path on rsync server configurations that allows uploading. Both possibilities are exposed only when chroot option is disabled. Workaround ========= You should never set the rsync daemon to run with "use chroot = false". Resolution ========= All users should update to the latest version of the rsync package. # emerge sync # emerge -pv "> =net-misc/rsync-2.6.0-r3" # emerge "> =net-misc/rsync-2.6.0-r3" References ========= [ 1 ] rsync Advisory [ 2 ] rsync 2.6.2 announcement Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200408-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
x-face-el does not take appropriate security precautions when creating temporary files.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 338-1
Get the latest Linux and open source security news straight to your inbox.